PT-2025-4763 · Sonicwall · Sonicwall Netextender

Published

2025-01-30

·

Updated

2025-02-04

·

CVE-2025-23007

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SonicWall NetExtender versions up to 10.3.0
Description A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.
Recommendations For SonicWall NetExtender versions up to 10.3.0, update to a version later than 10.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the log export function to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-23007

Affected Products

Sonicwall Netextender